Methodology
Our scoring model, false-positive philosophy, and confidence thresholds — explained honestly.
Signal vs verdict
A score above our alert threshold means a domain name looks statistically similar to something on your watch-list, and that similarity is unusual enough to warrant your attention. It does not mean:
Many matches are legitimate: a competitor who includes your brand name in a keyword, a parked domain purchased years ago, a security researcher's test environment. We state this clearly in every alert we send.
Thresholds
| Score | Delivery | Meaning |
|---|---|---|
| ≥ 90 | Immediate email | Strong match — review urgently |
| 50–89 | Daily digest | Plausible match — review when convenient |
| 20–49 | Internal log only | Weak signal — not delivered to you |
| < 20 | Discarded | Statistical noise |
Thresholds are adjustable per tenant. High-risk sectors (banking, crypto) typically lower the immediate alert threshold to 80 to catch more borderline cases.
Accuracy
An automated system running at CT-log scale will produce false positives. Our goal is to keep the ratio low enough that alerts remain actionable — not to eliminate false positives by raising the threshold, which would also eliminate true positives.
If you consistently see false-positive domains matching a particular pattern, you can add those patterns to your suppress-list and we'll filter them before delivery. Suppression rules are tunable without changing your alert threshold.
Scope
We are a detection system, not an investigation or remediation service. We don't:
For takedown and legal action, contact an IP or trademark attorney, or use your registrar's abuse mechanism.
Sources
We do not use active port scanning, vulnerability databases, or dark-web sources.